# How do perform string manipulations

**URL:** <https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706>\
**Category:** Logstash\
**Created:** [October 21, 2015, 5:34pm UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706 "2015-10-21T17:34:19Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![samnik60](https://avatars.discourse-cdn.com/v4/letter/s/b19c9b/32.png) [@samnik60](https://discuss.elastic.co/u/samnik60)\
**Post date:** [October 21, 2015, 5:34pm UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/1 "2015-10-21T17:34:19Z")

</div>

the string manipulations has been hard from me with logstash, how do i do substr(destinationid,instr(destinationid,"discard"),7)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 21, 2015, 6:21pm UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/2 "2015-10-21T18:21:48Z")

</div>

Wouldn't substr(destinationid,instr(destinationid,"discard"),7) always return "discard"? Perhaps you can give an example of an input string and the desired result.

---

<div class="post-metadata">

**Author:** ![samnik60](https://avatars.discourse-cdn.com/v4/letter/s/b19c9b/32.png) [@samnik60](https://discuss.elastic.co/u/samnik60)\
**Post date:** [October 21, 2015, 6:23pm UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/3 "2015-10-21T18:23:40Z")

</div>

destinationid=aadiscardsomething

it is for substr(destinationid,instr(destinationid,"discard"),14)

i want to extract "discardsome"

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 21, 2015, 8:09pm UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/4 "2015-10-21T20:09:29Z")

</div>

You can use a grok filter to extract strings from other strings.

```
grok {
  match => ["destinationid", "(?<fieldname>discard.{7})"]
}

```

This extracts a new field named `fieldname` from the field `destinationid`, starting with "discard" and followed by the seven characters thereafter, i.e. if `destinationid` contains "aadiscardsomething" then `fieldname` will contain "discardsomethi".

---

<div class="post-metadata">

**Author:** ![samnik60](https://avatars.discourse-cdn.com/v4/letter/s/b19c9b/32.png) [@samnik60](https://discuss.elastic.co/u/samnik60)\
**Post date:** [October 22, 2015, 6:43am UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/5 "2015-10-22T06:43:24Z")

</div>

Thanks a lot. Can u suggest some document which i can refer to avoid these queries in future 😄.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 22, 2015, 7:48am UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/6 "2015-10-22T07:48:09Z")

</div>

How about the [grok filter's documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)?

---

<div class="post-metadata">

**Author:** ![samnik60](https://avatars.discourse-cdn.com/v4/letter/s/b19c9b/32.png) [@samnik60](https://discuss.elastic.co/u/samnik60)\
**Post date:** [October 22, 2015, 7:52am UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/7 "2015-10-22T07:52:09Z")

</div>

Well its not much on examples or complete syntax ,  
for example i did see Custom Patterns but i couldnt figure out how to use it in the filter but  
after seeing your post grok {  
match =\> ["destinationid", "(?discard.{7})"]  
}  
now i get it . May be i will get used to this in a while.

For example now i am puzzled with what to do if i need the rest of the string without specifying length.

do i use  
grok {  
match =\> ["destinationid", "(?discard)"] , i guess i have to do trial and error  
}

Thanks,  
sam

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 22, 2015, 8:04am UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/8 "2015-10-22T08:04:55Z")

</div>

> Well its not much on examples or complete syntax ,

What part of the syntax isn't covered?

> For example now i am puzzled with what to do if i need the rest of the string without specifying length.

You mean all of the string from "discard" and onwards? Just use `(?<fieldname>discard.*)`.

> do i use  
> grok {  
> match =\> ["destinationid", "(?discard)"] , i guess i have to do trial and error  
> }

If you format the configuration snippets as code you won't run the risk of getting things stripped because the look like HTML (or whatever).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:25am UTC](https://discuss.elastic.co/t/how-do-perform-string-manipulations/32706/9 "2017-07-06T05:25:47Z")

</div>


